Important
My code lives on a self-hosted forge. All personal projects are at git.richardnixon.dev/explore/repos (Forgejo, behind the same Authentik SSO, CrowdSec WAF, and Prometheus/Loki/Grafana stack I write about). This GitHub account exists only for upstream OSS contributions — issues, PRs, forks against repos I don't own. Nothing here is a mirror. The forge is part of the threat model, not a side project.
Python & DevOps | AI/LLM Security · Detection Engineering · Counter-Intelligence Background Applied to Production Systems
A decade in Brazilian law enforcement and counter-intelligence — the operational kind, where logs are evidence, OPSEC isn't optional, and the threat model is named. Career arc: 911/NOC operations → mission-critical infrastructure for the 2014 FIFA World Cup (Elevated Observation Platform, airborne surveillance) → SRE at the Brazilian Ministry of Justice (8K+ users, national innovation award, trained 10,000+ officers) → Technology Advisor to the Presidential Crisis Management Office as the Federal Government's central intelligence representative during the country's largest national crisis.
Now at Logitech: Python backend engineer putting LLMs into production across 30+ locales, hardening an internal AI security platform (~25–30% per-agent overhead reduction without weakening coverage), and applying the same instincts — adversary-aware API design, structured telemetry built for detection, paranoid-by-default trust boundaries.
Pivoting deliberately toward DevSecOps and AI/LLM Security. PgDip Computing in Cybersecurity (Level 9 NFQ, ATU) starting September 2026, Springboard+ funded.
| Now | LLM pipeline engineering at Logitech — prompt injection surface, system-prompt leakage, output integrity across 30+ locales; internal AI security platform hardening |
| Then | 10 years in Brazilian law enforcement and federal counter-intelligence — operational comms, surveillance infrastructure, intelligence pipelines for national security decision-making |
| Building | Self-hosted security stack as a live lab — same SSO, same WAF, same SIEM-style pipeline I'd ship to a SOC |
| Studying | PgDip Computing in Cybersecurity (Level 9 NFQ), ATU — starting Sept 2026, Springboard+ funded |
| Platform | What's here |
|---|---|
| git.richardnixon.dev (Forgejo) | All personal projects — source of truth, issues, releases |
| github.com/richardnixondev | OSS contributions to upstream projects only — forks, PRs, issues. No personal repos. |
The self-hosted forge is dogfooding: same Authentik SSO, CrowdSec WAF, mTLS via Traefik, and Prometheus/Loki/Grafana pipeline I instrument and harden every day. If I write about a control, I run it.
- AI / LLM Security — adversarial testing of production LLM pipelines, prompt injection, system-prompt leakage, output integrity across multi-locale environments. Counter-intelligence lens applied to model behaviour and data flows.
- Detection Engineering — Sigma rules, log-based anomaly detection on a self-hosted stack (CrowdSec, Authentik, Prometheus/Loki/Grafana) I run end-to-end. Detection-as-code over dashboards-as-theatre.
- DevSecOps — secure API design, secrets hygiene, CI/CD hardening, observability as a detection surface
- Adversary-aware Backend Python — FastAPI / Django, REST APIs, LLM integration at scale; engineered for environments where logs are evidence
Security, Detection & Observability
Personal projects aren't on GitHub. Live catalogue at git.richardnixon.dev/explore/repos.
Current pipeline (Q2–Q3 2026):
- LLM Prompt Injection Detector — adversarial test harness for translation pipelines, collection-style logging
- Sigma Rules for Self-Hosted Stack — Authentik / Traefik / CrowdSec detections, mapped to MITRE ATT&CK
- Security write-ups — controlled disclosure, VDP acknowledgments
This account reflects contributions to projects maintained by others. Active interest areas: Forgejo, Authentik, CrowdSec, FastAPI, Django, detection tooling.